tmpca7b.tmp

The file tmpca7b.tmp has been detected as malware by 27 anti-virus scanners.
MD5:
1e2065d81a8001e228fd9336a9dda548

SHA-1:
3d3f488e416df1e6f38c1eb94be178550c566f24

SHA-256:
1fc0ab5f42d4356b9b10eb445c94ba62a61640e5de6db1d07076e0f6da08af52

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/26/2024 6:14:19 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2330808
623

AhnLab V3 Security
Trojan/Win32.Teslacrypt
2015.05.05

Avira AntiVirus
TR/Crypt.EPACK.Gen2
3.6.1.96

avast!
Win32:Malware-gen
2014.9-150522

AVG
FileCryptor
2016.0.3101

Baidu Antivirus
Backdoor.Win32.Zegost
4.0.3.15522

Bitdefender
Trojan.GenericKD.2330808
1.0.20.710

Bkav FE
HW32.Packed
1.3.0.6379

Dr.Web
Trojan.DownLoader13.4609
9.0.1.0142

Emsisoft Anti-Malware
Trojan.GenericKD.2330808
8.15.05.22.03

ESET NOD32
Win32/Injector.BZJU (variant)
9.11573

Fortinet FortiGate
W32/BZJU!tr
5/22/2015

F-Secure
Trojan.GenericKD.2330808
11.2015-22-05_6

G Data
Trojan.GenericKD.2330808
15.5.25

IKARUS anti.virus
Trojan.Crypt
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.203.15797

Kaspersky
Backdoor.Win32.Zegost
14.0.0.2002

McAfee
RDN/Ransom!ex
5600.6757

Microsoft Security Essentials
Ransom:Win32/Crowti
1.1.11602.0

MicroWorld eScan
Trojan.GenericKD.2330808
16.0.0.426

NANO AntiVirus
Trojan.Win32.Zegost.drcitc
0.30.24.1357

nProtect
Trojan.GenericKD.2330808
15.05.04.01

Panda Antivirus
Trj/Genetic.gen
15.05.22.03

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
Suspicious_GEN.F47V0429
7.2.142

VIPRE Antivirus
Trojan.Win32.Generic
39934

File size:
357.5 KB (366,080 bytes)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\tmpca7b.tmp

File PE Metadata
Compilation timestamp:
4/28/2015 4:48:46 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:1r62rwlhVrgAk3dg0jYxMH5vXvE8gzLAoKIj4kESwrSbg6gc8OOVtAdz01V4W:h62MrlZk3dgbMZfvE8kLzKIj4D+gIOVD

Entry address:
0x395C

Entry point:
E8, DE, 13, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2A, 83, 78, 10, 03, 75, 24, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 05, E8, 38, 14, 00, 00, 33, C0, 5D, C2, 04, 00, 68, 66, 39, 40, 00, FF, 15, 60, 80, 40, 00, 33, C0, C3, 8B, FF, 55, 8B, EC, 68, 98, 81, 40, 00, FF, 15, 64, 80, 40, 00, 85, C0, 74, 15, 68, 88, 81, 40, 00, 50, FF, 15, 30, 80, 40, 00, 85, C0, 74, 05, FF, 75...
 
[+]

Entropy:
6.4032

Code size:
27 KB (27,648 bytes)

Remove tmpca7b.tmp - Powered by Reason Core Security